I believe there's no comparison as Imperva is a much more reliable and powerfull WAF. AWS WAF lacks of several features Imperva have and is not that simple to configure neither have a clean web console. I consider Imperva WAF a whole superior level of cyber security solution …
Ultimately, it was the easiest to work with that was still a "known" company (we've been burned too many times by up-and-comers). We needed something that gave us a lot of control but then didn't need its handheld on a daily basis. Imperva gives us a lot of that and we are …
I recommend Imperva specially if you have a big environment with thousand of websites because of its ease to use and availability. Imperva delivers a reliable solution with great capability to contain cyber attacks and even fraud preventions in some cases. The only scenario it's less appropriate is if your focus is anti fraud instead of a solution to block cyber attacks.
Attack Correlation Validation - This specific policy produces a lot of false positives as well as the SQL injection policies. Of course it is difficult to tell what a legitimate query is on a public facing web app.
Profiling - I tend to spend more time than any other feature tuning the Web App Profiles. Plugins are used to help cope with this, but on extremely large web apps we are forced to turn off the profiling feature.
We haven't needed support from Imperva since implementation. But during that time, their personnel were very quick to respond to questions. Since then, it's been largely doing its thing for us (which is exactly what we'd hoped).
I believe there's no comparison as Imperva is a much more reliable and powerfull WAF. AWS WAF lacks of several features Imperva have and is not that simple to configure neither have a clean web console. I consider Imperva WAF a whole superior level of cyber security solution and it's consider to be one of the leader in this segment.
Better Insight into web application - Absolutely great, checks all the traffic against RFC standards and will alert on common development mistakes that duplicate application traffic or provide attack vectors for potential attackers.
Have had several issues blocking a customer without producing alerts, while it happened only one week out of 2 years of working with the devices, it did produce a lot of headaches.